VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-4217
tivoli_directory_server: Use-after-free vulnerability in the proxy server in...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4217

Original

Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-11-09
Source Information Category:
Advisory, Alert
Last Updated:
2010-11-10




Affected Product Tags
cpe:/a:ibm:tivoli_directory_server:6.0.0.0
cpe:/a:ibm:tivoli_directory_server:6.0.0.1
cpe:/a:ibm:tivoli_directory_server:6.0.0.14
cpe:/a:ibm:tivoli_directory_server:6.0.0.19
cpe:/a:ibm:tivoli_directory_server:6.0.0.33
cpe:/a:ibm:tivoli_directory_server:6.0.0.41
cpe:/a:ibm:tivoli_directory_server:6.0.0.45
cpe:/a:ibm:tivoli_directory_server:6.0.0.52
cpe:/a:ibm:tivoli_directory_server:6.0.0.53
cpe:/a:ibm:tivoli_directory_server:6.0.0.54
cpe:/a:ibm:tivoli_directory_server:6.0.0.55
cpe:/a:ibm:tivoli_directory_server:6.0.0.56
cpe:/a:ibm:tivoli_directory_server:6.0.0.57
cpe:/a:ibm:tivoli_directory_server:6.0.0.58
cpe:/a:ibm:tivoli_directory_server:6.0.0.59
cpe:/a:ibm:tivoli_directory_server:6.0.0.60
cpe:/a:ibm:tivoli_directory_server:6.0.0.61
cpe:/a:ibm:tivoli_directory_server:6.0.0.62
cpe:/a:ibm:tivoli_directory_server:6.0.0.63
cpe:/a:ibm:tivoli_directory_server:6.0.0.64
cpe:/a:ibm:tivoli_directory_server:6.0.0.7
cpe:/a:ibm:tivoli_directory_server:6.0.0.8
cpe:/a:ibm:tivoli_directory_server:6.1.0.0
cpe:/a:ibm:tivoli_directory_server:6.1.0.5
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
AIXAPAR IO13364




AIXAPAR IO13282




BID 44604




OSVDB 68964




SECTRACK 1024670




SECUNIA 42083




VUPEN ADV-2010-2863




VUPEN ADV-2010-2861




Vulnerability Type Resource Management Errors (CWE-399)





Copyright © 2010 JPCERT/CC All Rights Reserved.